MCP server providing access to Upstox trading and investment APIs, enabling retrieval of portfolio holdings, positions, orders, mutual funds, and IPO data with OAuth authentication
Strong naming and schema consistency across all 18 tools. All tools follow verb_noun convention with clear semantic distinctions (get-profile, get-holdings, get-positions, etc.). All input parameters have type definitions and descriptions. Tool descriptions are consistently 100-200+ characters, well above the 34-char floor. Error handling and recovery guidance are present but minimal, no actionable error messages or retryable/fatal classifications visible in code. Output schemas are not explicitly documented in the provided source. Authentication error metadata handling (applyAuthErrorMetadata) shows security awareness but no validation/sanitization logic visible. Read-only annotations are correctly applied to all tools. Tool composition is good, each tool has a single, focused responsibility. Response limiting is evident in MF order pagination (max 30) and IPO pagination (max 30), but no evidence of response field stripping for downstream chaining. Overall, this is a solid, production-ready tool collection with minor documentation gaps.
Retrieve fund balance and margin details for the user's account. Optionally scope to a segment: 'SEC' (equity/F&O) or 'COM' (commodity); omit to return both.
Retrieve long-term equity holdings — stocks retained across previous trading sessions — with current value, quantity, average price, and P&L.
Fetch the full public details of a single IPO, including face value, lot size, minimum quantity, cut-off price, prospectus links, registrar contact details and the allotment/listing/refund timeline. Requires the IPO id slug from get-ipos (for example autofurnish-limited-ipo).
Fetch full details of a specific IPO application (bid) the authenticated user has placed, including bids, allotment status, UPI mandate and payment information.
Fetch the authenticated user's own IPO applications (bids), including the bids placed, units allotted, application status, UPI mandate and payment status. Paginated. Use get-ipos for publicly listed IPOs.
Output schemas not documented in tool descriptions or handler code. LLMs cannot predict response structure or plan downstream chaining without explicit schema documentation.
Error responses lack actionable recovery guidance. Authentication errors set requiresReauth metadata but no error messages guide next steps. Non-existent resource errors should suggest alternatives or offer search_* paths.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 55 | - | v1 |
List publicly available IPOs on NSE/BSE with their price band, lot details, bidding window and subscription level. Filter by lifecycle status and market segment. This returns market-wide IPO data, not the user's own applications - use get-ipo-orders for those.
Retrieve the user's mutual fund holdings — units, last NAV, unrealized P&L, folio, and ISIN.
Retrieve a paginated list of mutual fund orders. Optional filters: status, transaction_type (BUY/SELL/ALL), page_number, records (max 30).
Get status and full details for a specific mutual fund order by orderId — fund, folio, amount, units, and execution details.
List the user's active and paused mutual fund SIP registrations. Paginated (records max 30).
Retrieve Margin Trade Funding (MTF) positions with quantity, value, and margin information.
Retrieve the complete order book for the trading day — all open, pending, filled, cancelled, and rejected orders.
Get the latest status and details for a specific order by its orderId, including execution state and fill information.
Retrieve the full state-transition history of an order from placement through execution or rejection. Provide orderId and/or tag to scope.
Retrieve all trades (fills) executed for a specific order — trade IDs, fill prices, and quantities — identified by orderId.
Retrieve current-day trading positions with real-time P&L, quantity, and margin details for all active intraday positions.
Fetch the authenticated Upstox user's profile: account details, enabled exchanges, supported order types, and product configurations.
Get all trades executed for the current trading day, including fill prices, quantities, and trade timestamps.
No visible input validation or sanitization. Parameters like orderId and ipoId are accepted as strings with no regex pattern, length check, or SQL/command injection guards documented.
Pagination and result limiting not uniformly applied. get-mf-order-book, get-mf-sips, get-ipos, and get-ipo-orders have explicit pagination with max 30, but no response stripping or large result handling guidance in descriptions.
Tool descriptions lack explicit dependency hints or prerequisites. No description states 'Requires authentication' or 'Call get-order-book first if you don't have an orderId'. This forces LLMs to guess multi-step sequences.